The VentureBeat June 2026 Pulse Research survey, which polled 107 qualified enterprises with more than 100 employees, found that 54% have already experienced an AI agent security incident or near-incident. Of those, 18% confirmed an actual incident, while 36% reported a near-miss.

The credentials problem is worse than you think

A full 69% of enterprises admitted to operating AI agents using shared credentials. Only 32% provide each agent with its own scoped identity. In English: most companies are handing their AI bots the same username and password, which means if one agent gets compromised, attackers potentially get the keys to everything that credential touches.

Isolation controls aren’t much better. Only 30% of enterprises sandbox their high-risk AI agents. A third of respondents said their security budget allocation specifically for agent security sits at 5% or less.

Bigger companies, bigger problems